
Adobe stock
As Canada's Critical Cyber Systems Protection Act moves into implementation, attention turns to the regulations that will determine how it is applied in practice. Canada now finds itself at an important crossroads. Will the regulations emphasize the development of effective security programs that can adapt their technical controls over time? Will they focus on compliance with prescribed standards? Or will they ultimately land somewhere between the two?
This is not the first time these questions have emerged. Performance-based regulation has long been discussed in sectors such as transportation. While attractive in principle, these approaches can quickly devolve into compliance regimes centred on managing plans rather than achieving outcomes. More traditional compliance models, meanwhile, are well established within the governance, risk and compliance community. Over time, however, they often become exercises in obtaining the certification required to operate rather than building genuine security capability.
With the legislation now in place, the drafting of regulations is where the real work begins. Those regulations will shape how a significant portion of Canada's critical infrastructure approaches cyber security, including third-party and supply chain risk. Before we sharpen the pencils too quickly, three challenges deserve careful consideration.
Build flexibility into the framework
The first challenge is accommodating the scope, scale and speed of technological change.
Regulations evolve deliberately. The processes that govern their development are intended to prevent unintended consequences, avoid unnecessary burdens and close potential gaps. While that pace can seem slow in many areas of public policy, the difference between regulatory change and the rate at which information technology evolves can seem nothing short of astronomical.
The implication is clear: regulations must provide sufficient flexibility to remain relevant as technology continues to evolve.
Develop technical capability, not just compliance expertise
The second challenge is addressing the education, skills and training gaps that will inevitably emerge.
Canada likely has a solid base of professionals capable of reviewing programs from a documentation and governance perspective. The greater challenge lies in developing the technical expertise needed to operate, assess and secure increasingly complex systems.
Cyber security education must extend beyond explaining frameworks and demonstrating compliance with standards. It must prepare practitioners to sit in front of an administrator's console, understand how systems actually operate, identify emerging risks and respond without creating the very disruptions they are attempting to prevent.
Building that capability will be every bit as important as building the regulatory framework itself.
Reflect the realities of modern infrastructure
The third challenge is recognizing the realities of today's interconnected systems.
Organizations increasingly depend on external infrastructure, cloud services and global technology providers. Regulations must account for that reality.
What happens when a company operating outside Canada provides critical services within Canada but declines to participate in Canada's regulatory regime? Addressing these situations requires more than rigid compliance requirements. It demands regulations that recognize there may be multiple approaches to managing security risk while still achieving acceptable outcomes.
That flexibility will require both practical experience and sound judgment throughout the regulatory development process.
From legislation to implementation
This is the time to engage industry, encourage meaningful consultation and begin establishing a trusted advisory community willing to contribute beyond immediate commercial interests.
The Critical Cyber Systems Protection Act represents an important step forward. The work ahead will determine whether Canada's regulatory framework strengthens cyber security or simply expands compliance obligations. As regulations take shape, there is an opportunity to pursue approaches that balance security, innovation and operational reality while accommodating the diverse viewpoints that inevitably accompany meaningful regulatory reform.









